A 1.2.0 release of roundcubemail fixed an XSS vulnerability in href attribute on area tag. External references: https://github.com/roundcube/roundcubemail/issues/5240 Upstream fix: https://github.com/roundcube/roundcubemail/pull/5241
Created roundcubemail tracking bugs for this issue: Affects: fedora-all [bug 1339655] Affects: epel-all [bug 1339656]
CVE assignment: http://seclists.org/oss-sec/2016/q2/414
roundcubemail-1.2.0-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
roundcubemail-1.2.0-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
roundcubemail-1.2.0-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
CVE-2016-5103 has been rejected in favour of CVE-2016-4552.